<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to merge and map two splunk multi value fields and creating a seperate field? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-merge-and-map-two-splunk-multi-value-fields-and-creating/m-p/622402#M216343</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;We have below data extracted in splunk and the ask is , in the "Node" field we need to make first two values as one value, next two values as one value and so on and map these values to the corresponding COUNT value.&lt;/P&gt;&lt;P&gt;For Eg: in the first row in "Node" field , we need to create three separate values of consecutive two values and map these values to corresponding COUNT value.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DarshanBK_0-1669725742015.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/22693i49F97454621F4334/image-size/medium?v=v2&amp;amp;px=400" role="button" title="DarshanBK_0-1669725742015.png" alt="DarshanBK_0-1669725742015.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;expected result:&lt;/P&gt;&lt;P&gt;COUNT&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Node&lt;/P&gt;&lt;P&gt;682&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;gol************,ser****&lt;/P&gt;&lt;P&gt;---------------------------------------------------------&lt;/P&gt;&lt;P&gt;622&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;gol************,ser****&lt;/P&gt;&lt;P&gt;----------------------------------------------------------&lt;/P&gt;&lt;P&gt;606&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;gol************,ser****&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Note: *********** is just for masking not the requirement. Only above format is the requirement.&lt;/P&gt;&lt;P&gt;COUNT and Node are multi value fields and we need single value fields in above format&lt;/P&gt;&lt;P&gt;Can someone please help me in achieving this. I have spent 2 days and not getting the solution.&lt;/P&gt;&lt;P&gt;Any help would be appreciated a lot.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;</description>
    <pubDate>Tue, 29 Nov 2022 12:48:27 GMT</pubDate>
    <dc:creator>DarshanBK</dc:creator>
    <dc:date>2022-11-29T12:48:27Z</dc:date>
    <item>
      <title>How to merge and map two splunk multi value fields and creating a seperate field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-merge-and-map-two-splunk-multi-value-fields-and-creating/m-p/622402#M216343</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;We have below data extracted in splunk and the ask is , in the "Node" field we need to make first two values as one value, next two values as one value and so on and map these values to the corresponding COUNT value.&lt;/P&gt;&lt;P&gt;For Eg: in the first row in "Node" field , we need to create three separate values of consecutive two values and map these values to corresponding COUNT value.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DarshanBK_0-1669725742015.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/22693i49F97454621F4334/image-size/medium?v=v2&amp;amp;px=400" role="button" title="DarshanBK_0-1669725742015.png" alt="DarshanBK_0-1669725742015.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;expected result:&lt;/P&gt;&lt;P&gt;COUNT&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Node&lt;/P&gt;&lt;P&gt;682&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;gol************,ser****&lt;/P&gt;&lt;P&gt;---------------------------------------------------------&lt;/P&gt;&lt;P&gt;622&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;gol************,ser****&lt;/P&gt;&lt;P&gt;----------------------------------------------------------&lt;/P&gt;&lt;P&gt;606&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;gol************,ser****&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Note: *********** is just for masking not the requirement. Only above format is the requirement.&lt;/P&gt;&lt;P&gt;COUNT and Node are multi value fields and we need single value fields in above format&lt;/P&gt;&lt;P&gt;Can someone please help me in achieving this. I have spent 2 days and not getting the solution.&lt;/P&gt;&lt;P&gt;Any help would be appreciated a lot.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Tue, 29 Nov 2022 12:48:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-merge-and-map-two-splunk-multi-value-fields-and-creating/m-p/622402#M216343</guid>
      <dc:creator>DarshanBK</dc:creator>
      <dc:date>2022-11-29T12:48:27Z</dc:date>
    </item>
    <item>
      <title>Re: How to merge and map two splunk multi value fields and creating a seperate field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-merge-and-map-two-splunk-multi-value-fields-and-creating/m-p/622421#M216359</link>
      <description>&lt;P&gt;I'd try looking into your pipeline somewhere earlier. With multivalued fields there is no guarantee that the results from one fields will be in the order corresponding to the other field.&lt;/P&gt;&lt;P&gt;Is this a result of some summarization command or you're getting the data as some ugly json/xml which gets parsed this way?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Nov 2022 14:07:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-merge-and-map-two-splunk-multi-value-fields-and-creating/m-p/622421#M216359</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-11-29T14:07:11Z</dc:date>
    </item>
    <item>
      <title>Re: How to merge and map two splunk multi value fields and creating a seperate field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-merge-and-map-two-splunk-multi-value-fields-and-creating/m-p/622424#M216360</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;index=*&lt;/P&gt;&lt;P&gt;source=*&lt;BR /&gt;|rename facets{}.total.results{}.count AS COUNT,facets{}.name{} as Node&lt;BR /&gt;|table _time,COUNT,Node&lt;/P&gt;&lt;P&gt;Above is the simple SPL i'm using.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;As you mentioned the data is&amp;nbsp; json/xml which gets parsed this way.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Nov 2022 14:18:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-merge-and-map-two-splunk-multi-value-fields-and-creating/m-p/622424#M216360</guid>
      <dc:creator>DarshanBK</dc:creator>
      <dc:date>2022-11-29T14:18:39Z</dc:date>
    </item>
    <item>
      <title>Re: How to merge and map two splunk multi value fields and creating a seperate field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-merge-and-map-two-splunk-multi-value-fields-and-creating/m-p/622427#M216362</link>
      <description>&lt;P&gt;I'd try parsing the fields differently (spath and mvsplit?) so it doesn't aggregate as much. Because as I said - there is no guarantee on the order and contents of multivalued fields so even if you did some mvfunctions() magic in order to get the values, it will fall apart completely if for some reason you had one value missing or you had them reordered or whatever.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Nov 2022 14:25:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-merge-and-map-two-splunk-multi-value-fields-and-creating/m-p/622427#M216362</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-11-29T14:25:24Z</dc:date>
    </item>
    <item>
      <title>Re: How to merge and map two splunk multi value fields and creating a seperate field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-merge-and-map-two-splunk-multi-value-fields-and-creating/m-p/622568#M216428</link>
      <description>&lt;P&gt;This how the data is coming into splunk. gol********* and serv******** are coming in as multiple values in a single field. Where as our requirement is to capture them as single field and corresponding count in "total" element.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DarshanBK_2-1669795774564.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/22713iC1DF6B89F86F527B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="DarshanBK_2-1669795774564.png" alt="DarshanBK_2-1669795774564.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Like this in facets there are more facets.name entries and corresponding count which we need to extract. But when we use auto extracted field below is what we&amp;nbsp; are getting all in facets.name values captured as multivalue filed. Whereas we need seperate row for each facets.name entry.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DarshanBK_1-1669795753249.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/22712i992EAD17F9B87B3F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="DarshanBK_1-1669795753249.png" alt="DarshanBK_1-1669795753249.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Nov 2022 08:11:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-merge-and-map-two-splunk-multi-value-fields-and-creating/m-p/622568#M216428</guid>
      <dc:creator>DarshanBK</dc:creator>
      <dc:date>2022-11-30T08:11:02Z</dc:date>
    </item>
    <item>
      <title>Re: How to merge and map two splunk multi value fields and creating a seperate field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-merge-and-map-two-splunk-multi-value-fields-and-creating/m-p/622601#M216449</link>
      <description>&lt;P&gt;You can use spath to "pick out" separate parts of the main json. This way you can do a multivalued field with the "subjsons". Something akin to this (run anywhere example):&lt;/P&gt;&lt;PRE&gt;| makeresults&lt;BR /&gt;| eval json="{\"a\":[{\"b\":\"c\"},{\"b\":\"e\"}]}"&lt;BR /&gt;| spath input=json path="a{}" output=a&lt;BR /&gt;| mvexpand a&lt;BR /&gt;| spath input=a&lt;/PRE&gt;&lt;P&gt;This is of course a very simple json but you can similarily "untangle" much more complicated structures so you get each substructure into a separate event.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Nov 2022 11:22:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-merge-and-map-two-splunk-multi-value-fields-and-creating/m-p/622601#M216449</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-11-30T11:22:33Z</dc:date>
    </item>
  </channel>
</rss>

